# Australian Authorities Arrest Two Men in Connection with Prolific Software Supply Chain Attack Group
## Major Cybercrime Syndicate Dismantled After Months-Long Investigation
Australian law enforcement has made a significant breakthrough in combating cybercrime, with the arrest of two young men from Western Australia suspected of belonging to one of the most persistent and damaging software supply chain attack groups ever documented. The Australian Federal Police (AFP) confirmed the detentions in a statement released this week, describing the operation as the dismantling of a “sophisticated cybercrime syndicate” that allegedly weaponized open-source software to rob thousands of businesses worldwide.
The two suspects, aged 21 and 23, were taken into custody in Perth. Reports indicate that one suspect, identified as Ruben Ian Thomson of Cottesloe, was denied bail and will remain in detention until a scheduled court appearance on September 18. The second suspect, 23-year-old Michael Gaebler, also faces multiple charges. Together, the pair are confronting 14 separate cybercrime offenses.
## Understanding the Group’s Modus Operandi
The group at the center of this investigation gained notoriety for a unique and devastating approach to cybercrime: infiltrating the open-source software ecosystem and using compromised developer credentials to inject malicious code into widely-used programming tools. This method — known as a software supply chain attack — exploits the trust that developers place in freely available code libraries.
According to cybersecurity analysts, the group’s core tactic involved a cyclical exploitation process. First, attackers would gain unauthorized access to development environments where open-source tools were being maintained. They would then embed malware into these tools. When other developers downloaded and used the compromised software, the malware would steal their credentials — which the attackers would then use to publish their own malicious versions of other popular development tools. This self-reinforcing cycle allowed the group to grow its network of compromised systems exponentially.
The group also employed a controversial recruitment strategy. In one notable instance, they published the source code for a self-propagating piece of malware online and launched a contest offering cryptocurrency prizes to whoever could compromise the most software packages. Participants were scored based on the number of downloads of the packages they had poisoned — effectively turning the contest into a talent-scouting and access-acquisition operation.
## Notable Attacks and Victims
The group’s campaign of digital extortion has touched numerous high-profile organizations across multiple industries. In early 2026, the group executed a major supply chain attack against LiteLLM, an open-source artificial intelligence platform that connects users to more than 100 different large language models. A subsequent analysis by cybersecurity firm CloudSEK revealed the attack harvested cloud service credentials and other sensitive data from over 2,500 organizations, including many of the world’s leading technology companies.
Earlier that same year, the group claimed responsibility for compromising at least 3,800 code repositories at GitHub, a Microsoft-owned code-sharing platform, after a developer installed a code extension that had been tampered with by the group’s malware. The breach prompted Microsoft to accelerate long-overdue security reforms at GitHub.
Beyond the technology sector, the group’s data broker affiliates sold information stolen from breaches at major automotive manufacturers including BMW Group, Audi, Honda, Mercedes-Benz, Volvo, and Toyota, as well as data reportedly taken from Snapchat and the sports data company SportRadar. Another associated entity claimed credit for extortion attacks against pharmaceutical giant Novo Nordisk, the data broker LexisNexis, and Avnet, a Fortune 500 distributor of electronic components.
## The Network Behind the Attacks
Cybersecurity investigators describe the group not as a single, structured criminal organization, but rather as a peer community of individually skilled threat actors united around a central coordinating figure. The group communicated through a private messaging server on the Matrix platform, which had been set up under the name “Cybercats” and had attracted members affiliated with multiple distinct cybercrime operations.
The central figure, operating under the online handle @kernelstub, is described by analysts as an accomplished security researcher and exploit developer. Through this platform, the group coordinated attacks, shared stolen data, and publicly taunted victims before incidents were reported in the media. Several members of the network maintained active presence on social media platforms, where they posted about their activities and targeted organizations.
## How the Investigation Unfolded
The investigation that led to the arrests drew on a combination of digital forensics, open-source intelligence gathering, and cross-referencing of online activity across multiple platforms. Investigators traced the group’s digital footprints through forum registrations, social media accounts, email addresses, and IP addresses, gradually building a picture that linked online aliases to real-world identities.
One key breakthrough came when investigators discovered that the group’s spokesperson had posted content on social media that revealed geographic details linking him to Western Australia. Further digital forensics connected multiple online personas — used across cybercrime forums, messaging platforms, and social media — to a small cluster of individuals living in the Perth area.
The suspects reportedly had a documented history of substance abuse and mental health challenges, which investigators say contributed to patterns of behavior that ultimately exposed their identities. Despite the group’s technical sophistication, investigators note that operational security failures — including the reuse of email addresses, phone numbers, and personal details across multiple platforms — proved to be their undoing.
## Broader Implications for Software Security
The group’s activities have had a transformative impact on the cybersecurity industry, forcing major technology platforms to overhaul their security practices. In direct response to the wave of supply chain attacks, GitHub introduced a three-day “cooldown” mechanism for its automated dependency update tool, Dependabot, in late 2026. The feature is designed to delay the automatic installation of new package updates, giving security teams time to identify and remove compromised versions before they propagate to users.
Other major software ecosystems, including Python’s package repository and various JavaScript platforms, have also adopted similar cooldown protections in recent months. Security researchers have credited the group’s attacks with achieving in a matter of months what the broader security community had been pushing for over several years.
Analysts warn, however, that the rise of artificial intelligence and large language models is lowering the barrier to entry for sophisticated cybercrime operations. What previously required years of specialized knowledge and operational discipline can now be partially automated, creating an environment where capable but reckless actors can cause significant damage at scale.
—
## Frequently Asked Questions (FAQ)
**What is a software supply chain attack?**
A software supply chain attack occurs when a malicious actor compromises a software tool, library, or update mechanism that is widely used by developers or organizations. Because the targeted software is trusted, the malicious code is automatically distributed to all users who download or update the compromised tool — potentially affecting thousands or even millions of systems.
**Why are open-source repositories a common target?**
Open-source repositories like GitHub and npm (the JavaScript package registry) host code that millions of developers rely on daily. When an attacker compromises a popular open-source project, they can potentially affect a vast number of downstream users with a single injection, making these platforms attractive targets.
**What is the Shai-Hulud worm?**
Shai-Hulud is a self-propagating piece of malware associated with the cybercrime group at the center of this case. It was designed to automatically add malicious code to open-source programs maintained by developers whose credentials had been stolen or phished at public code repositories. The worm’s ability to spread autonomously made it a particularly potent tool for large-scale supply chain compromise.
**What are the charges faced by the suspects?**
The two men arrested in Western Australia face a combined total of 14 cybercrime offenses. Specific charges have not been publicly detailed by the Australian Federal Police, though the offenses are understood to relate to the creation and deployment of malicious software, unauthorized access to computer systems, and data extortion.
**How did the group recruit new members?**
The group used a controversial contest model, offering cryptocurrency prizes to participants who could compromise the most software packages using a provided malware tool. Participants were scored based on download numbers of the poisoned packages, creating a direct incentive to target the most popular code libraries. Investigators describe this as a talent-identification and access-acquisition strategy.
**What was the group’s connection to South Africa?**
Digital forensics indicate that the group’s primary operator lived in South Africa for at least part of the time the attacks were being carried out. Internet address connections traced to South African residential and mobile networks, and the operator used email accounts and online identities registered from South African IP addresses during the earliest phase of the campaign.
**What has been the long-term impact on software security practices?**
The group’s activities have accelerated the adoption of several security measures across the software development ecosystem, including cooldown periods for automated dependency updates, improved credential protection for open-source maintainers, and increased scrutiny of third-party code contributions to major repositories. Security experts say the group’s actions — while harmful — have driven meaningful and lasting improvements.
—
## Conclusion
The arrest of these two individuals marks a significant milestone in the global fight against cybercrime, particularly in the realm of software supply chain attacks — a threat vector that has grown exponentially in recent years. The case illustrates both the remarkable capabilities and the critical vulnerabilities of modern cybercriminal operations.
While the group’s technical sophistication allowed it to compromise some of the most widely used development platforms in the world, its ultimate undoing came from a combination of operational carelessness and the tireless work of digital investigators who meticulously traced digital breadcrumbs across multiple platforms and jurisdictions.
The ripple effects of this group’s activities will be felt for years to come — not only in the strengthened security measures now implemented by platforms like GitHub and others, but also in the broader conversation about how open-source ecosystems can be protected in an era when artificial intelligence is rapidly lowering the technical barriers to cybercrime.
This case also raises important questions about the social and psychological dimensions of cybercrime. Reports indicate that the group’s leader struggled with substance abuse and mental health issues throughout the operation, suggesting that the individuals behind these attacks are not simply faceless criminals, but complex human beings whose personal circumstances intersected with digital opportunity in devastating ways.
As the suspects await their day in court, the cybersecurity community remains vigilant, recognizing that while this particular syndicate may have been disrupted, the underlying vulnerabilities in the global software supply chain — and the incentives that attract talented individuals to the dark side of cybercrime — remain very much alive.
Thank you for reading.



